Data First Jobs

FUSTIS LLC

Identity & Data Security Engineer

Contract · In Office · USA

$70,000–$75,000 · Posted Jul 31, 2026

Work Options
Cloud Stack
Job Type
Position Group
  • Job Title: Identity & Data Security Engineer - 11100
  • Location: DFW, TX – Hybrid
  • Duration: 12 Months
  • Work Authorization: USC, GC, GC-EAD and H4-EAD
  • Pay Rate: $75/hr. on W2

Job Description:

  • Identity & Data Security Engineer
  • Description:
  • Operationalize automated data discovery, classification, and inventory; apply sensitivity labels and consistent taxonomy across data stores, pipelines, and collaboration systems.
  • Engineer DSPM capabilities with tools (e.g., Securiti, BigID) to surface data posture risks (overexposure, shadow data, stale sensitive data) and drive remediation workflows.
  • Implement and support encryption, tokenization, masking, anonymization/pseudonymization for data at rest and in transit; integrate with cloud key management systems and enforce approved cryptographic standards; define crypto baselines and policy-as-code guardrails.
  • Configure and govern access controls with RBAC/ABAC and purpose-based authorization; perform least-privilege and fine-grained access reviews across data platforms.
  • Deploy, tune, and operate DLP and DAM solutions (e.g., Microsoft Purview DLP, Imperva/Guardium); build detections for PII/PCI/PHI and reduce false positives with policy and context improvements.
  • Integrate and tune UEBA and Insider Risk signals to detect anomalous data access and exfiltration, partner on response workflows and preventive control changes.
  • Integrate data protection telemetry with SIEM/SOAR; build detections, correlation rules, and automated response playbooks for data-related threats and policy violations.
  • Implement data minimization and retention/ROT enforcement patterns; automate monitoring of lifecycle actions (archive, delete, redact) aligned to policy and legal holds.
  • Implement DSAR (data subject access request) orchestration and fulfillment with SLA monitoring; automate data collection, redaction, and secure delivery with audit trails.
  • Contribute to cookie/tag governance and catalog assurance; validate consent signals, storage durations, and vendor script behavior against policy.
  • Support privacy platform capabilities and integrate with identity, ticketing, data catalogs/lineage, and evidence repositories.
  • Embed data protection and privacy-by-design controls into services and CI/CD (pre-commit/CI privacy code scanning, secret scanning, schema checks for sensitive fields, data egress policies).
  • Produce compliance evidence and reports for GDPR/CCPA/CPRA, PCI DSS, HIPAA, and internal audits; maintain controls health dashboards, regulatory tracking, and program KPIs.
  • Investigate data-related incidents and privacy events in partnership with IR/SOC/Privacy Office. Collect artifacts, support forensics, document findings, and drive preventive engineering fixes.
  • Conduct platform hardening and vulnerability remediation for data control tooling (misconfigurations, exposed buckets, weak crypto, excessive permissions).
  • Participate in red teaming/tabletop exercises for data scenarios (insider misuse, public link exposures, unintended AI training data); translate findings into control improvements.
  • Partner with Cybersecurity, Privacy Office, Enterprise Data, Legal, and product/platform teams to align designs and deliver privacy- and data protection-by-design outcomes.
  • Document engineering patterns, runbooks, and reference architectures; create training and technical guidance that strengthen secure data handling practices across teams.
  • Communicate clearly and concisely with technical and non‑technical audiences - summarize incidents, risks, and recommended actions with accurate, complete context.
  • Required Skills & Experience
  • 3–7 years of hands-on experience in:
  • Active Directory administration/engineering
  • Microsoft Entra ID (Azure AD)
  • Azure AD Connect / hybrid identity environments
  • Experience with:
  • AD security hardening
  • Identity-related attack techniques (privilege escalation, lateral movement)
  • Attack path analysis or remediation activities
  • Strong working knowledge of:
  • Tier 0 concepts and identity as a control plane
  • Authentication protocols (Kerberos, NTLM, SAML, OAuth)
  • Preferred Experience
  • Exposure to:
  • CyberArk or other PAM tools
  • Saviynt or similar IGA platforms
  • Ping Identity or federation solutions
  • HashiCorp Vault, Keyfactor, or PKI environments
  • Experience supporting AD forest recovery exercises
  • Familiarity with Zero Trust principles
  • Key Traits for Success
  • Strong execution and delivery focus
  • Security and resiliency mindset
  • Ability to quickly identify and remediate risks
  • Works effectively in a cross-functional cybersecurity environment
  • Comfortable working in fast-paced, project-driven (contract) engagements

Mention you found this on Data First Jobs — it helps us bring you more roles like this.

Identity & Data Security Engineer

FUSTIS LLC

Like this role? Get carefully selected jobs like it, twice a week, straight to your inbox.

Free, no spam. Unsubscribe anytime.